CVE-2026-43670

A Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5. Processing maliciously crafted web content may bypass Content Security Policy.
References
Link Resource
https://support.apple.com/en-us/127110 Vendor Advisory Release Notes
https://support.apple.com/en-us/127111 Vendor Advisory Release Notes
https://support.apple.com/en-us/127115 Vendor Advisory Release Notes
https://support.apple.com/en-us/127121 Vendor Advisory Release Notes
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apple:safari:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-25 20:16

Updated : 2026-08-27 17:14


NVD link : CVE-2026-43670

Mitre link : CVE-2026-43670

CVE.ORG link : CVE-2026-43670


JSON object : View

Products Affected

apple

  • iphone_os
  • ipados
  • safari
  • macos
CWE
CWE-693

Protection Mechanism Failure